Take urgent steps to bring the data breach to an end

The incident management team should take steps to:

  • stop any continuing data breach
  • prevent any repeat or related future data breach. Where it is not possible to stop the data breach immediately, take such steps as are possible to mitigate any ongoing data breach. Some of the measures you might consider, if appropriate, include: 
    • changing back-up procedures
    • securing any data over which security may have been lost, but which is still within the company’s control
    • introducing immediate security measures (eg encryption) in relation to work-related devices (eg laptops, smartphones)
    • introducing or increasing employee email/internet surveillance (taking care to comply with relevant monitoring or data privacy restrictions)
  • if possible, recover any data which may have been lost 
  • consider legal action to restrain any further data breach or to prevent any third party using or disclosing inappropriately acquired data